SB2018020806 - Denial of service in Cisco Virtualized Packet Core



SB2018020806 - Denial of service in Cisco Virtualized Packet Core

Published: February 8, 2018

Security Bulletin ID SB2018020806
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Denial of service (CVE-ID: CVE-2018-0117)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software due to improper handling of user-supplied input. A remote attacker can send malicious traffic to the internal distributed instance (DI) network address, trigger an unhandled error condition, cause the CF instances and the entire VPC to reload, resulting in the disconnection of all subscribers and denial of service.

Remediation

Install update from vendor's website.